CybersecurityJobs.io
← Back to all jobs

Job Description

Moody’s Identity Engineering team is responsible for designing, building, and operating identity and access management platforms that secure access across Moody’s enterprise and regulated environments. In this onsite role in Golden, CO, you will support Identity and Access Management end to end, spanning workforce identity engineering in Okta, SSO integrations, authentication and MFA policies, provisioning automation, and audit-ready operations. You will also provide engineering coverage for Microsoft Entra ID and Conditional Access within regulated contexts.

What you’ll do

  • Own end-to-end engineering, configuration, and administration of workforce identities in Moody’s Okta tenants, including the FedRAMP workforce, non-production, and Customer Identity and Access Management tenants, applying established standards and requirements
  • Design and maintain Single Sign-On and application integrations using SAML, OIDC, and SCIM across enterprise applications
  • Engineer authentication and multi-factor authentication policy to enforce a phishing-resistant assurance level
  • Own identity lifecycle (joiner/mover/leaver) and provisioning workflows, including automation via Okta Workflows
  • Monitor and respond to identity risk signals and threats
  • Design and administer groups, custom admin roles, and least-privilege access models
  • Produce and maintain SOX and FedRAMP audit evidence in partnership with Cybersecurity Governance and Audit teams
  • Provide engineering coverage for Microsoft Entra ID, including Conditional Access policy design and hybrid identity management configurations
  • Support hybrid identity operations and coordinate with the Entra/Active Directory engineering owner on shared administrative responsibilities per the team’s admin-ownership model

Requirements

  • 3+ years of hands-on access management engineering experience, including workforce identity configuration, administration, and lifecycle management (Okta preferred)
  • Strong depth in core Identity and Access Management and Single Sign-On protocols and application integration patterns, including SAML, OIDC, and SCIM
  • Experience engineering authentication and multi-factor authentication policy using phishing-resistant methods
  • Hands-on experience with identity lifecycle and provisioning automation
  • Experience operating in regulated, audited environments (SOX/ITGC, FedRAMP, or equivalent), including producing audit evidence and control documentation
  • Working knowledge of identity governance concepts such as access requests, certifications, and separation of duties; Okta Identity Governance experience is preferred
  • Familiarity with Microsoft Entra ID administration, including Conditional Access policy engineering and hybrid identity management, is preferred
  • Strong written communication skills for producing audit-ready documentation and evidence packages
  • Ability to independently lead end-to-end engineering work from requirements through operational support
  • Demonstrated proficiency in artificial intelligence concepts, with hands-on experience using AI tools to streamline workflows and enhance operational efficiency, plus growing awareness of AI risk management and a commitment to responsible and ethical AI use

Technologies

  • Okta
  • SAML
  • OIDC
  • SCIM
  • Okta Workflows
  • Okta Identity Governance
  • Microsoft Entra ID
  • Conditional Access
  • FedRAMP
  • SOX
  • ITGC
  • Microsoft Active Directory

Benefits

  • Incentive compensation
  • Medical, dental, vision
  • Parental leave
  • Paid time off
  • 401(k) plan with employee and company contribution opportunities
  • Life, disability, and accident insurance
  • Discounted employee stock purchase plan
  • Tuition reimbursement

Additional qualifications

  • Advanced technical certifications preferred, such as Okta Certified Administrator/Professional (Consultant a plus), Microsoft Certified: Identity and Access Administrator (SC-300), CISSP, or equivalent identity/security certifications
  • Prior FedRAMP or US federal identity/compliance experience preferred

Education

Bachelor’s degree or equivalent qualification in Computer Science, Information Technology, Cybersecurity, Engineering, o

Location: Golden, CO (onsite). Compensation: USD 116,500 - 192,300 per yearly.

Similar Jobs